{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:703ff5c4-9ec6-5e9e-a386-cedce7eff715",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/upgrade",
      "purl": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5",
      "version": "8.2.14-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b82b1de7-c958-5feb-a35d-8d34958f6813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:73026601-609b-5cf3-9d38-1cdd019e16b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d95d1e59-3daa-57af-90a5-84e6f9c7fd1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:63364b61-0782-5f6e-9b63-756a324a7b2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8837465f-0f3f-5ee2-9fca-e178b87b6e78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0a9ff1a1-f019-5ef7-b0b0-7076c7011fcd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:35b29597-88aa-5b22-80b8-286e18293991",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aad342c6-34ed-5ab1-bf6d-26de9edfb625",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:11538cad-0639-5867-994c-dc6f463ba2ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:76dc3a49-6625-5d16-9ad0-fee49d6c74d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:196d5492-12dc-581b-bd93-b11ff2f83cbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fb514af6-7692-5726-948b-8a6739de7431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e2d79003-4d15-5161-bab8-287f4529acb3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0e7c29ea-8965-5ac6-b663-008fb93e2873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:58e4850a-92d5-5057-b3f8-6a66ea5f87f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cc033fa1-6425-511e-9924-a4c3c2a31792",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5d279252-cdd3-5efb-82fd-9eee12761aed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:42f74605-dd8b-58e8-813e-7acd2170136c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c15c37ef-e8aa-54c0-ba62-111861fd1e7a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:927c0da4-5efb-5466-b82e-ac344e2cd012",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:10e92d5a-0284-5b45-874d-4b1b8c412b1c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.5 of @angular/upgrade. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:57b143c9-6a9a-59f1-a765-6ae20ae6d48d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4880ded2-2f4f-5a2b-8d85-7a296f91137e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.5 of @angular/upgrade, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:35697208-103d-5056-a580-2155a3960e2b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.5 of @angular/upgrade. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a4d7a57e-94e7-5269-8210-b4f7187d891e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.5 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:28cc1019-f171-5cf7-8bec-0460996fb7a6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.5 of @angular/upgrade. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7b08941d-474a-58b0-bc15-8e988b8bb45c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.5 of @angular/upgrade."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@8.2.14-tuxcare.5"
    }
  ]
}